CVE-2023-54087
published 2025-12-24CVE-2023-54087: In the Linux kernel, the following vulnerability has been resolved: ubi: Fix possible null-ptr-deref in ubi_free_volume() It willl cause null-ptr-deref in the…
PriorityP420low5.5
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-deref in the following case:
uif_init()
ubi_add_volume()
cdev_add() -> if it fails, call kill_volumes()
device_register()
kill_volumes() -> if ubi_add_volume() fails call this function
ubi_free_volume()
cdev_del()
device_unregister() -> trying to delete a not added device,
it causes null-ptr-deref
So in ubi_free_volume(), it delete devices whether they are added
or not, it will causes null-ptr-deref.
Handle the error case whlie calling ubi_add_volume() to fix this
problem. If add volume fails, set the corresponding vol to null,
so it can not be accessed in kill_volumes() and release the
resource in ubi_add_volume() error path.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 5558bcf1c58720ca6e9d6198d921cb3aa337f038 | 5558bcf1c58720ca6e9d6198d921cb3aa337f038 |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 45b2c5ca4d2edae70f19fdb086bd927840c4c309 | 45b2c5ca4d2edae70f19fdb086bd927840c4c309 |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 234c53e57424992e657e6f4acc00d3df0983176f | 234c53e57424992e657e6f4acc00d3df0983176f |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < fcbc795abe7897da4b5d2a6ab5010e36774b00c2 | fcbc795abe7897da4b5d2a6ab5010e36774b00c2 |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 5ec4c8aca5a221756a9007deadfea92795319fee | 5ec4c8aca5a221756a9007deadfea92795319fee |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 2ea7195b195009ecf0046e55361f393ba96d02db | 2ea7195b195009ecf0046e55361f393ba96d02db |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < 9eccdb0760cbcb4427b5303a83a3007de998af51 | 9eccdb0760cbcb4427b5303a83a3007de998af51 |
| linux | linux | >= 801c135ce73d5df1caf3eca35b66a10824ae0707 < c15859bfd326c10230f09cb48a17f8a35f190342 | c15859bfd326c10230f09cb48a17f8a35f190342 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 2.6.22 < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 4.15.0 < 4.19.276 | 4.19.276 |
| linux | linux_kernel | >= 4.20.0 < 5.4.235 | 5.4.235 |
| linux | linux_kernel | >= 5.11.0 < 5.15.100 | 5.15.100 |
| linux | linux_kernel | >= 5.16.0 < 6.1.18 | 6.1.18 |
| linux | linux_kernel | >= 5.5.0 < 5.10.173 | 5.10.173 |
| linux | linux_kernel | >= 6.2.0 < 6.2.5 | 6.2.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54087: In the Linux kernel, the following vulnerability has been resolved: ubi: Fix possible null-ptr-deref in ubi_free_volume() It willl cause null-ptr-dere
osv·2025-12-24
CVE-2023-54087 CVE-2023-54087: In the Linux kernel, the following vulnerability has been resolved: ubi: Fix possible null-ptr-deref in ubi_free_volume() It willl cause null-ptr-dere
In the Linux kernel, the following vulnerability has been resolved: ubi: Fix possible null-ptr-deref in ubi_free_volume() It willl cause null-ptr-deref in the following case: uif_init() ubi_add_volume() cdev_add() -> if it fails, call kill_volumes() device_register() kill_volumes() -> if ubi_add_volume() fails call this function ubi_free_volume() cdev_del() device_unregister() -> trying to delete a not added device, it causes null-ptr-deref So in ubi_free_volume(), it delete devices whether they are added or not, it will causes null-ptr-deref. Handle the error case whlie calling ubi_add_volume() to fix this problem. If add volume fails, set the corresponding vol to null, so it can not be accessed in kill_volumes() and release the resource in ubi_add_volume() error path.
OSV
ubi: Fix possible null-ptr-deref in ubi_free_volume()
osv·2025-12-24
CVE-2023-54087 ubi: Fix possible null-ptr-deref in ubi_free_volume()
ubi: Fix possible null-ptr-deref in ubi_free_volume()
In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-deref in the following case:
uif_init()
ubi_add_volume()
cdev_add() -> if it fails, call kill_volumes()
device_register()
kill_volumes() -> if ubi_add_volume() fails call this function
ubi_free_volume()
cdev_del()
device_unregister() -> trying to delete a not added device,
it causes null-ptr-deref
So in ubi_free_volume(), it delete devices whether they are added
or not, it will causes null-ptr-deref.
Handle the error case whlie calling ubi_add_volume() to fix this
problem. If add volume fails, set the corresponding vol to null,
so it can not be accessed in kill_volumes() and release the
GHSA
GHSA-9w7w-3xjc-3wgw: In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-de
ghsa_unreviewed·2025-12-24
CVE-2023-54087 GHSA-9w7w-3xjc-3wgw: In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-de
In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-deref in the following case:
uif_init()
ubi_add_volume()
cdev_add() -> if it fails, call kill_volumes()
device_register()
kill_volumes() -> if ubi_add_volume() fails call this function
ubi_free_volume()
cdev_del()
device_unregister() -> trying to delete a not added device,
it causes null-ptr-deref
So in ubi_free_volume(), it delete devices whether they are added
or not, it will causes null-ptr-deref.
Handle the error case whlie calling ubi_add_volume() to fix this
problem. If add volume fails, set the corresponding vol to null,
so it can not be accessed in kill_volumes() and release the
resource in ubi_add_volume() error path.
Red Hat
kernel: Linux kernel (UBI): Denial of Service due to improper error handling
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54087 [LOW] CWE-476 kernel: Linux kernel (UBI): Denial of Service due to improper error handling
kernel: Linux kernel (UBI): Denial of Service due to improper error handling
In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-deref in the following case:
uif_init()
ubi_add_volume()
cdev_add() -> if it fails, call kill_volumes()
device_register()
kill_volumes() -> if ubi_add_volume() fails call this function
ubi_free_volume()
cdev_del()
device_unregister() -> trying to delete a not added device,
it causes null-ptr-deref
So in ubi_free_volume(), it delete devices whether they are added
or not, it will causes null-ptr-deref.
Handle the error case whlie calling ubi_add_volume() to fix this
problem. If add volume fails, set the corresponding vol to null,
so it can not be accessed in kill_volumes(
Debian
CVE-2023-54087: linux - In the Linux kernel, the following vulnerability has been resolved: ubi: Fix po...
vendor_debian·2023
CVE-2023-54087 CVE-2023-54087: linux - In the Linux kernel, the following vulnerability has been resolved: ubi: Fix po...
In the Linux kernel, the following vulnerability has been resolved: ubi: Fix possible null-ptr-deref in ubi_free_volume() It willl cause null-ptr-deref in the following case: uif_init() ubi_add_volume() cdev_add() -> if it fails, call kill_volumes() device_register() kill_volumes() -> if ubi_add_volume() fails call this function ubi_free_volume() cdev_del() device_unregister() -> trying to delete a not added device, it causes null-ptr-deref So in ubi_free_volume(), it delete devices whether they are added or not, it will causes null-ptr-deref. Handle the error case whlie calling ubi_add_volume() to fix this problem. If add volume fails, set the corresponding vol to null, so it can not be accessed in kill_volumes() and release the resource in ubi_add_volume() error path.
Scope: local
bookwo
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54087 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54087 CVE-2023-54087 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54087 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-deref in the following case:
uif_init()
ubi_add_volume()
cdev_add() -> if it fails, call kill_volumes()
device_register()
kill_volumes() -> if ubi_add_volume() fails call this function
ubi_free_volume()
cdev_del()
device_unregister() -> trying to delete a not added device,
it causes null-ptr-deref
So in ubi_free_volume(), it delete devices whether they are added
or not, it will causes null-ptr-deref.
Handle the error case whlie calling ubi_add_volume() to fix this
problem. If add volume fails, set the corresponding vol to null,
so it can not be accessed in kill_volumes
Bugzilla
CVE-2023-54087 kernel: Linux kernel (UBI): Denial of Service due to improper error handling
bugzilla·2025-12-24
CVE-2023-54087 [LOW] CVE-2023-54087 kernel: Linux kernel (UBI): Denial of Service due to improper error handling
CVE-2023-54087 kernel: Linux kernel (UBI): Denial of Service due to improper error handling
In the Linux kernel, the following vulnerability has been resolved:
ubi: Fix possible null-ptr-deref in ubi_free_volume()
It willl cause null-ptr-deref in the following case:
uif_init()
ubi_add_volume()
cdev_add() -> if it fails, call kill_volumes()
device_register()
kill_volumes() -> if ubi_add_volume() fails call this function
ubi_free_volume()
cdev_del()
device_unregister() -> trying to delete a not added device,
it causes null-ptr-deref
So in ubi_free_volume(), it delete devices whether they are added
or not, it will causes null-ptr-deref.
Handle the error case whlie calling ubi_add_volume() to fix this
problem. If add volume fails, set the corresponding vol to null,
so it can not be acce
https://git.kernel.org/stable/c/234c53e57424992e657e6f4acc00d3df0983176fhttps://git.kernel.org/stable/c/2ea7195b195009ecf0046e55361f393ba96d02dbhttps://git.kernel.org/stable/c/45b2c5ca4d2edae70f19fdb086bd927840c4c309https://git.kernel.org/stable/c/5558bcf1c58720ca6e9d6198d921cb3aa337f038https://git.kernel.org/stable/c/5ec4c8aca5a221756a9007deadfea92795319feehttps://git.kernel.org/stable/c/9eccdb0760cbcb4427b5303a83a3007de998af51https://git.kernel.org/stable/c/c15859bfd326c10230f09cb48a17f8a35f190342https://git.kernel.org/stable/c/fcbc795abe7897da4b5d2a6ab5010e36774b00c2
2025-12-24
Published